sbomify logo

The sbomify Blog

Content for software, product, and digital security experts

Blog

Securing the Software Supply Chain with SLSA: What You Need to Know

Abstract In a world where software is integral to almost every aspect of life, securing the software supply chain is more critical than ever. The increasing complexity of...

By Cowboy Neil // Aug 17. 2024

Understanding in-toto: Securing the Software Supply Chain

In today’s software landscape, securing the software supply chain is more crucial than ever. With increasing concerns about vulnerabilities and supply chain attacks, developers and organizations are looking...

By Cowboy Neil // Aug 14. 2024

Understanding Sigstore: Securing the Software Supply Chain

Summary: In an era where software supply chain attacks are becoming more common and sophisticated, Sigstore represents a critical advancement in securing software development practices. By lowering the...

By Cowboy Neil // Aug 12. 2024

Understanding Lock File Drift: A Hidden Risk in Dependency Management

In the world of software development, managing dependencies is crucial for ensuring the stability and security of applications. One often overlooked aspect of this process is the phenomenon...

By Cowboy Neil // Jul 31. 2024

How to Generate SBOMs for Python Packages with `pipdeptree` and `cyclonedx-py`

Software Bill of Materials (SBOMs) are essential for ensuring transparency and security in software supply chains. This guide will show you how to use pipdeptree and cyclonedx-py to...

By Viktor // Jul 30. 2024

Embracing Cybersecurity with CISA's 'Secure by Design' Initiative

In the ever-evolving landscape of cyber threats, the importance of integrating robust security measures into the earliest stages of software development cannot be overstated. Recognizing this need, the...

By Cowboy Neil // Jul 24. 2024

What's New in SPDX 3: Enhanced Referencing Capabilities

At sbomify, we pride ourselves on providing the latest insights and updates in the realm of Software Bill of Materials (SBOM). One of the most anticipated developments is...

By Cowboy Neil // Jul 22. 2024

Understanding the EU Cyber Resilience Act: The Role of SBOMs in Enhancing Cybersecurity

In an era where digital transformation is the norm, cybersecurity has become a paramount concern for organizations and governments worldwide. The European Union (EU) is at the forefront...

By Cowboy Neil // Jul 10. 2024

The Role of SBOMs in an OBOM: Ensuring Compliance and Security in Smart Thermometer Development

In today’s software landscape, compliance with security and transparency mandates is more critical than ever. Executive orders, such as the one issued by the U.S. government in May...

By Cowboy Neil // Jul 9. 2024

Enhancing Dependency Management with GitHub's Dependency Graph: An Analysis

Introduction

By Cowboy Neil // Jun 24. 2024

Framing Software Component Transparency: Establishing a Common Software Bill of Materials (SBOM)

As the digital world grows ever more complex, the tools we use to ensure software security and transparency must evolve. The 2nd edition of Framing Software Component Transparency:...

By Cowboy Neil // Jun 11. 2024

Get the latest SBOMs from the top 15 most popular images on Docker Hub

Most companies that use Docker also use Docker Hub in some capacity. Have you ever wondered how secure these images are? In our article Comprehensive Guide to Generating...

By Cowboy Neil // Jun 4. 2024